CVE-2026-36213 is a local privilege escalation vulnerability affecting Microvirt MEmu Android Emulator version 9.2.7.0. The issue is reported to reside in the MemuService.exe component. Based on the available information, a local attacker can abuse this component to obtain elevated privileges on the host system. Specific technical details about the vulnerable code path, root cause, and exploitation method are not available in the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This three-file repository contains a standalone Python local privilege-escalation PoC, an Apache 2.0 license, and a README. The Python entry point targets Microvirt MEmu Android Emulator 9.2.7.0 on Windows, specifically the SYSTEM-level MEmuSVC service and its default MemuService.exe binary. It invokes icacls and considers the target vulnerable when its output contains BUILTIN\Users or Everyone together with a Full Control marker, then writes embedded C# source to a temporary file and compiles it with csc.exe. The script backs up MemuService.exe, overwrites it with the generated payload, and attempts `sc stop`/`sc start` on MEmuSVC. The generated executable records `whoami` output in a Windows Temp marker file, intended to prove SYSTEM execution after service restart or reboot. No remote hosts, URLs, IP addresses, or network communication are present. The ACL check is simplistic and may produce false positives because it does not associate a specific `(F)` permission with the matched principal; additionally, a low-privileged user may need an administrator, reboot, or another mechanism to trigger service restart.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.